Forum Discussion

helpmef5_35924's avatar
helpmef5_35924
Icon for Nimbostratus rankNimbostratus
Sep 21, 2012

SSL Server self-signed certificate

Hi everyone,

 

 

I have an issue getting a VIP set up. I'd like to have it so that users can go to a simple URL (e.g. http://callmanager) which would resolve in DNS to the VIP address. I'd like the F5 to be able to take that HTTP request and initiate a HTTPS session to the Call Manager servers on a specific URL. So ideally, all HTTPS traffic remains between the Call Manager web server and the F5 box and the client only has to worry about HTTP traffic. One other kink in the whole mess is that the Call Manager web server utilizes a self-signed certificate. Can anyone provide some assistance? Thanks in advance.

 

 

1 Reply

  • Hamish's avatar
    Hamish
    Icon for Cirrocumulus rankCirrocumulus
    Yes. Thats possible. Its essentially ssl offload in reverse.

     

     

    The self signed cert between f5 and callmanager won't matter to bigip by default. Just create a standard host virtual sever and add a serverssl profile to it (the default one named serverssl will work fine)

     

     

    Worst case yo will have to do some rewriting. That could be from none to needing something like the ProxyPass iRule. Or some simple stream based translation.. Ymmv.

     

     

     

    H